Malware

Zusy.311480 (file analysis)

Malware Removal

The Zusy.311480 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.311480 virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Zusy.311480?


File Info:

crc32: C960F6D2
md5: 10419c97cde1aa8bad4e33279a15f7f8
name: offer order.exe
sha1: b2942c499632593cface5c1fd18c12105656bf75
sha256: aa840ddac1cbded575db7d3ee2d1e3102fd1c35d0a709f42209543f9913e438f
sha512: c77bc2ead1869aced4a8e2955317c5cf99bbb68e35d54ec4d8794a6794bf3dda3b24764c8ce21bddf9ff09372565f08e3191a2c46fcbbfaaf649fa5f47bab0bc
ssdeep: 24576:fMCc4FpC8Fkjb0jztrXF0rEuZgMlXIqOUArsqmyiSCyiSVUJEq7zvVJf9w9:f3h0rjZVhlZfyiSCyiSV/CznFw9
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 1998-2017 Mark Russinovich
InternalName: Process Explorer
FileVersion: 16.21
CompanyName: Sysinternals - www.sysinternals.com
LegalTrademarks: Copyright (C) 1998-2017 Mark Russinovich
ProductName: Process Explorer
ProductVersion: 16.21
FileDescription: Sysinternals Process Explorer
OriginalFilename: Procexp.exe
Translation: 0x0409 0x04e4

Zusy.311480 also known as:

MicroWorld-eScanGen:Variant.Zusy.311480
FireEyeGeneric.mg.10419c97cde1aa8b
CAT-QuickHealTrojan.Wacatac
McAfeeFareit-FVP!10419C97CDE1
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan-Downloader ( 0056ca6c1 )
BitDefenderGen:Variant.Zusy.311480
K7GWTrojan-Downloader ( 0056ca6c1 )
CyrenW32/Trojan.LTRY-3799
SymantecML.Attribute.HighConfidence
APEXMalicious
KasperskyHEUR:HackTool.Win32.Agent.gen
AlibabaTrojan:Win32/Ymacco.eb74cd6e
RisingDownloader.Delf!8.16F (CLOUD)
Ad-AwareGen:Variant.Zusy.311480
EmsisoftGen:Variant.Zusy.311480 (B)
F-SecureHeuristic.HEUR/AGEN.1104233
DrWebTrojan.PWS.Spy.21482
ZillyaDownloader.Delf.Win32.59697
TrendMicroTrojan.Win32.WACATAC.USXVPHI20
SophosMal/Generic-S
IkarusTrojan.Inject
JiangminAdWare.Generic.qvve
AviraHEUR/AGEN.1104233
MAXmalware (ai score=87)
Antiy-AVLTrojan[Downloader]/Win32.Delf
MicrosoftTrojan:Win32/Ymacco.AAAA
ArcabitTrojan.Zusy.D4C0B8
ZoneAlarmHEUR:HackTool.Win32.Agent.gen
GDataGen:Variant.Zusy.311480
CynetMalicious (score: 85)
AhnLab-V3Malware/Win32.RL_Generic.R347077
BitDefenderThetaGen:NN.ZelphiCO.34196.VL3@aizSH6ii
ALYacGen:Variant.Zusy.311480
MalwarebytesTrojan.MalPack.DLF
ZonerTrojan.Win32.92359
ESET-NOD32a variant of Win32/Kryptik.HFQY
TrendMicro-HouseCallTrojan.Win32.WACATAC.USXVPHI20
TencentMalware.Win32.Gencirc.10cdeb60
SentinelOneDFI – Suspicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Malicious_Behavior.VEX
AVGWin32:Malware-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Generic/Trojan.b75

How to remove Zusy.311480?

Zusy.311480 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment